Re: validating ... bad cache hit

2020-04-24 Thread Tony Finch
Havard Eidnes via bind-users wrote: > > If it was due to validation failure, I would have thought that it > would be more persistent than only last for 10 minutes. Looking for vaguely plausible causes I guess what might have happened is there was a DNSKEY lookup failure (transient network problem

Re: validating ... bad cache hit

2020-04-24 Thread Havard Eidnes via bind-users
>> [...] There are two invocations of dns_resolver_addbadcache() in >> lib/dns/resolver.c, with fairly complicated preconditions to reach >> each of those two points. > > I've had a very quick look at the code, and it looks to me like one > case is due to lack of authoritative server IP addresses,

Re: validating ... bad cache hit

2020-04-24 Thread Tony Finch
Havard Eidnes via bind-users wrote: > > Looking at the code in BIND 9.14.10 (BIND 9.16.2 doesn't appear to be > significantly different in this regard), there appears to be a "cache > of bad records" implemented by lib/dns/badcache.c. There are two > invocations of dns_resolver_addbadcache() in l

validating ... bad cache hit

2020-04-24 Thread Havard Eidnes via bind-users
Hi, we got reports about a temporary resolution failure for some names under norid.no this morning. Digging through the logs, the first instance appears to be Apr 24 08:35:02 resolver named[244]: validating zabbix-test.norid.no/CNAME: bad cache hit (norid.no/DNSKEY) and a couple of minutes lat